Description
Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory.
Published: 2026-07-10
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper input validation in Samsung Pass before version 5.2.10.3 permits a local privileged attacker to write data beyond the intended memory buffer. This out‑of‑bounds write can corrupt memory structures and potentially allow the attacker to execute arbitrary code or elevate privileges. The description does not detail downstream effects, but an out‑of‑bounds write in a security‑related component strongly suggests that severe impacts such as code execution could be achievable.

Affected Systems

Samsung Pass on Samsung mobile devices running any version earlier than 5.2.10.3. Versions 5.2.10.3 and later are assumed to contain the fix, as the description specifies the vulnerability exists only before this release.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity, while the EPSS score of less than 1% signals a very low‑but non‑zero likelihood of being exploited. The flaw is not listed in CISA KEV. Exploitation requires local privileged access; the attacker must be able to provide crafted input to the vulnerable application, leading to possible arbitrary code execution or privilege escalation.

Generated by OpenCVE AI on August 3, 2026 at 04:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Samsung Pass to version 5.2.10.3 or later to eliminate the input validation flaw.
  • If an upgrade is not available or feasible, uninstall or disable Samsung Pass to remove the attack surface.
  • Restrict local privileged accounts that can interact with Samsung Pass to reduce the likelihood of successful exploitation.

Generated by OpenCVE AI on August 3, 2026 at 04:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Write in Samsung Pass Allows Local Privileged Exploits
Weaknesses CWE-122

Fri, 24 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Samsung Pass Out-of-Bounds Memory Write Leading to Local Privilege Escalation
Weaknesses CWE-119
CWE-416

Tue, 21 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Samsung Pass Out-of-Bounds Memory Write Leading to Local Privilege Escalation
Weaknesses CWE-119
CWE-416

Fri, 17 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Samsung Pass Local Privilege Escalation via Out-of-Bounds Write
Weaknesses CWE-122
CWE-20
CWE-787

Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Samsung Pass Local Privilege Escalation via Out-of-Bounds Write
Weaknesses CWE-122
CWE-20
CWE-787

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Out-of-Bounds Write in Samsung Pass
Weaknesses CWE-120

Mon, 13 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Out-of-Bounds Write in Samsung Pass
Weaknesses CWE-120

Sun, 12 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Out‑Of‑Bounds Memory Write in Samsung Pass via Improper Input Validation
Weaknesses CWE-120
CWE-787

Fri, 10 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Out‑Of‑Bounds Memory Write in Samsung Pass via Improper Input Validation
Weaknesses CWE-120
CWE-787

Fri, 10 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Samsung Mobile
Samsung Mobile samsung Pass
Vendors & Products Samsung Mobile
Samsung Mobile samsung Pass

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Description Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory.
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Samsung Mobile Samsung Pass
cve-icon MITRE

Status: PUBLISHED

Assigner: SamsungMobile

Published:

Updated: 2026-07-10T11:30:25.418Z

Reserved: 2025-12-11T01:33:35.821Z

Link: CVE-2026-21057

cve-icon Vulnrichment

Updated: 2026-07-10T11:30:19.464Z

cve-icon NVD

Status : Deferred

Published: 2026-07-10T05:16:36.453

Modified: 2026-07-10T17:56:00.910

Link: CVE-2026-21057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T04:15:03Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow